CVE-2006-6634: High severity Mambo Extcalthai Module vulnerability
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (comextcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIGEXT[LANGUAGESDIR] parameter to adminevents.php, (2) the mosConfigabsolutepath parameter to extcalendar.php, or (3) the CONFIGEXT[LIBDIR] parameter to lib/mail.inc.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6634?
CVE-2006-6634 is considered a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2006-6634?
To fix CVE-2006-6634, upgrade to a version of the ExtCalThai component for Mambo that is later than 0.9.1.
What systems are affected by CVE-2006-6634?
CVE-2006-6634 specifically affects Mambo installations using the ExtCalThai component version 0.9.1 and earlier.
What type of vulnerability is CVE-2006-6634?
CVE-2006-6634 is classified as a remote file inclusion vulnerability.
Can CVE-2006-6634 be exploited remotely?
Yes, CVE-2006-6634 can be exploited remotely by attackers to execute arbitrary PHP code.